Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

07fly

First CVE: Jun 2, 2023Active for: 3 yearsTotal CVEs: 14
16.7
VTI Score
Low

07fly operates a modestly represented content-management and customer-relationship-management platform portfolio that skews toward serious outcomes, with a meaningful share of its vulnerabilities reaching critical severity. The recurrent exposure across its CMS and CRM products centers on web-application layer weaknesses including cross-site request forgery, unrestricted file upload, cross-site scripting, SQL injection, and missing authorization checks—patterns characteristic of input validation and access-control gaps in web-facing applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by 07fly over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 2, 2023
3 years ago
Most Recent CVE
Jul 6, 2025
383 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-25379CRITICAL
Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the id parameter of the del.html component.
Feb 28, 20259.626NONO
CVE-2023-5020CRITICAL
A vulnerability, which was classified as critical, has been found in 07FLY CRM V2. This issue affects some unknown processing of the file /index.php/sysmanage/Login/login_auth/ of
Sep 17, 20239.826NONO
CVE-2024-9904HIGH
A vulnerability classified as critical was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This vulnerability affects the function pictureUpload of the file /admin/File/pict
Oct 13, 20247.221NONO
CVE-2024-9903HIGH
A vulnerability classified as critical has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This affects the function fileUpload of the file /admin/File/fileUpload. The
Oct 12, 20247.221NONO
CVE-2024-9855HIGH
A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been declared as critical. Affected by this vulnerability is the function uploadFile of the file /admin/
Oct 11, 20247.221NONO
CVE-2023-3058MEDIUM
A vulnerability was found in 07FLY CRM up to 1.2.0. It has been declared as problematic. This vulnerability affects unknown code of the component User Profile Handler. The manipula
Jun 2, 20235.419NONO
CVE-2025-7078MEDIUM
A vulnerability classified as problematic was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.3.9. This vulnerability affects unknown code. The manipulation leads to cross-site r
Jul 6, 20254.316NONO
CVE-2024-51156MEDIUM
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component 'erp.07fly.net:80/admin/SysNotifyUser/del.html?id=93'.
Nov 14, 20244.716NONO
CVE-2024-51157MEDIUM
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component http://erp.07fly.net:80/oa/OaSchedule/add.html.
Nov 8, 20244.716NONO
CVE-2024-9856MEDIUM
A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been rated as problematic. Affected by this issue is some unknown functionality of the component System
Oct 11, 20244.816NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
14%
50%
21%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (28.6%)
Unknown0 (0.0%)
Required10 (71.4%)
Privileges Required
Low1 (7.1%)
High6 (42.9%)
None7 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by 07fly.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by 07fly — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For 07fly's Products

View all 2 CNAs →

Top CWEs